Spring Gift, 1200 at Registration, Reel Vegas Online Casino
Authentication-Results: mta1091.mail.ukl.yahoo.com from=; domainkeys=neutral (no sig);
from=alpilles-luberon-immobilier.com; dkim=neutral (no sig)
Received: from 127.0.0.1 (HELO 218-210-035-203.catvisp.net.tw) (126.96.36.199)
by mta1091.mail.ukl.yahoo.com with SMTP; Wed, 21 Apr 2010 21:15:07 -0700
Date: Thu, 22 Apr 2010 00:09:53 -0500
From: "Reel Casino©" <GeorgiaCooper@alpilles-luberon-immobilier.com>
Subject: Spring gift, €1200 at registration
Content-Type: text/html; charset=iso-8859-1
You do not presume to go to Las Vegas - anything terrible then Las Vegas will arrive to you.
Huge choice of games online, on interest and on money.
In our casino money will be strewed to you to hands as snow, without a stop.
It is luxury which you presume. Receive yours €1200 at registration
So do not put off that you can make today.
The e-mail contains a link to an advertising page for the Reel Vegas Online Casino. Almost every link on this page points to an executable file called reelvegasen.exe. Jotti's malware scan delivered no results for this specific file. (Click here for the scan results).
Even if the file isn't malware, you still shouldn't trust it. There is absolutely no guarantee that the information you submit through this software will be treated confidentially. Your personal details may be shared with 3rd parties, resulting in more spam, your credit card details may be stolen, resulting in fraudulent transactions being processed on your credit card or even worse, your identity might be stolen. The possibilities for problems are endless.
Closer inspection of the file revealed that it is an installer for the Royal Vegas Online Casino gambling software (provided by FortuneLounge) and not Reel Vegas Online Casino, as advertised on the spammer's web page. So the spammer is most likely an affiliate of FortuneLounge, or more precisely, FortuneAffiliates.
The spamvertised website was registered by a Sun Qiang from China on 2010-04-12 17:05:28 (the spam e-mail apparently originated from Taiwan). Details about other Casino Spam sites, registered by the same spammer, can be found at malwareurl.com. We noticed that each site was registered a couple of seconds after the other one, so this spammer has been a busy boy (or girl).
The WHOIS information of these sites also appears to be invalid, because the Nameservers for these domains are listed as ns1.bestseasilver.com and ns2.bestseasilver.com, a suspended domain registered on 20 March 2010, to Yuri Vernitsky from Russia, but a traceroute revealed 188.8.131.52 (China Telecom) as the IP address for these sites (no reverse DNS entry was found for this IP address). So we guess that explains the funny English in this e-mail.
The Registrar of Sun Qiang's Casino Spam sites, is BEIJING INNOVATIVE LINKAGE TECHNOLOGY LTD, a registrar known for being in breach of ICANN's RAA in the past, but they are also known as one of the registrars who apparently got their act together, after receiving a breach notice from ICANN. So is history repeating itself?
Preview of the spamvertised site:
Related Cyber Criminal Profiles:No related profiles found.
Similar Spam Examples:Seven Stars Online Casino - Spring gift, 1000 at registration
World Casino Online Gambling Spam
BlackJack Ballroom - Your ticket number could be a winner
Anonymous Online Casino Spam
Casino Action Spam - You are among the winners